Skip to main content
Build an AI Transparency Program Before AugustPrivacy & Data Governance
6 min readFor Compliance Training Managers

Build an AI Transparency Program Before August

The Spanish Data Protection Authority issued a formal notice on January 13, 2026, about the risks of using AI tools with images. The European Commission published its first draft Code of Practice on Transparency of AI-Generated Content. These aren't theoretical warnings. The AI Act's transparency obligations apply from August 2026. If your organization uses AI to generate, modify, or process images, text, or video, you need working controls now.

This guide walks you through building a compliance program that meets the incoming requirements. You don't need a legal degree. You need a clear process.

Why This Matters Now

When an employee uploads someone's photo to an AI tool, they're processing personal data under GDPR. When your marketing team uses AI to create content, you'll need to label it clearly starting in August. The Spanish DPA's notice makes this explicit: feeding an image into an AI system triggers legal obligations, even if you never share the output.

The risks fall into two categories. Visible risks occur when you share AI-generated content: deepfakes, misattribution, content taken out of context. Less visible risks happen behind the scenes: loss of control when third-party providers process the data, undisclosed secondary processing, metadata that enables re-identification.

You're also facing non-data-protection risks. Copyright claims. Misuse of someone's likeness. Reputational damage from AI-generated content that looks real but isn't. The August deadline isn't far away. Start building your program now.

What You Need Before Starting

Before you implement controls, gather these resources:

Inventory of AI tools. List every AI system your organization uses or allows employees to access. Include image generators, chatbots that accept file uploads, video editing tools with AI features, and any internal systems that process personal data through AI.

Stakeholder team. You need representatives from legal, IT, communications, HR, and any department that regularly creates content. Don't try to build this alone.

Access to vendor contracts. Pull the agreements for every AI tool you use. You'll need to understand what happens to data after upload, where it's stored, and whether the provider uses it for training.

Documentation template. Create a simple log to track which AI systems you've reviewed, what controls you've applied, and when you last updated the assessment.

Step-by-Step Implementation

Step 1: Map your AI use cases

Start with a spreadsheet. For each AI tool, document: what it does, which departments use it, what type of content it processes (images, text, video), and whether it handles personal data. Don't skip the obvious ones. If someone can upload a photo, it processes personal data.

Ask each department: "What AI tools do you use in your daily work?" You'll discover shadow IT. Marketing might use one image generator. Sales might use another. IT might not know about either.

Step 2: Classify your content

The draft Code of Practice introduces two categories: fully AI-generated content and AI-assisted content where AI substantially influences the output. For each use case, decide which category applies.

Fully AI-generated: an image created entirely by an AI tool with no human-created source material. AI-assisted: a photo you edited using AI filters, or text you drafted and then refined with AI suggestions.

Write down your classification rules. "If we upload an employee photo and apply AI filters, that's AI-assisted. If we generate a stock image from a text prompt with no source photo, that's fully AI-generated."

Step 3: Build your labeling system

The Code requires clear labeling using a common icon. The official EU icon isn't ready yet, so you can use an interim icon: a two-letter acronym like "AI," "IA," or "KI" depending on your language.

Create templates for different content types:

  • Static images: Add the icon in a visible corner with sufficient contrast.
  • Real-time video: Display a continuous on-screen indicator plus an opening notice.
  • Non-real-time video: Choose from fixed icons, opening notices, or credits-based disclosure.
  • Text content: Include a disclosure statement at the beginning or end.

Document your labeling standards in a one-page guide. Make it specific: "Place the AI icon in the bottom-right corner, minimum 20px height, with a white background if the image is dark."

Step 4: Implement upload safeguards

Any time someone uploads an image containing a person, they're processing personal data. You need safeguards before the upload happens.

Create a pre-upload checklist:

  • Do you have a legal basis to process this person's image?
  • Is the person identifiable in the photo?
  • Have you reviewed the AI tool's data processing terms?
  • Do you need this person's consent?
  • Could this create reputational or privacy risks?

Add this checklist to your acceptable use policy. Train employees to pause before uploading, not after.

Step 5: Document your practices

The Code requires deployers to document labeling practices. Create a simple log with these columns: content type, AI tool used, classification (fully generated or assisted), labeling method applied, date created, and who approved it.

Update this log every time you create AI-generated content. It takes 30 seconds per entry. It proves you have a system.

Step 6: Set up training and monitoring

Schedule quarterly training for anyone who creates content. Cover: which AI tools are approved, how to classify content, how to apply labels, and what the risks are.

Assign someone to review published content monthly. Check that labels are present and correct. If you find mislabeling, document it and correct it immediately. The Code requires a channel for reporting mislabeling, so set up an email address or form where employees can flag issues.

How to Verify It Works

Run these checks to confirm your program is functioning:

Spot-check published content. Pull five pieces of content created in the last month that used AI. Verify each one has the correct label in the correct format. If you find unlabeled content, trace back to find where the process broke down.

Test the reporting channel. Have someone outside your team submit a test report about mislabeled content. Confirm you receive it and can respond within 24 hours.

Review vendor contracts. For each AI tool, confirm you understand: where data is stored, whether the vendor uses uploaded content for training, how long data is retained, and whether you can request deletion. If you can't answer these questions, you don't have adequate safeguards.

Audit your inventory. Compare your AI tool inventory against IT's approved software list and against credit card statements. You're looking for tools people are using that aren't on your list.

Ongoing Tasks

Your program isn't static. Set these recurring tasks:

Monthly: Review new content for labeling compliance. Update your documentation log. Check for new AI tools in use.

Quarterly: Deliver refresher training. Review and update your classification rules based on new use cases. Test your reporting channel.

Annually: Re-assess all vendor contracts. Update your acceptable use policy. Review whether your labeling format still meets regulatory guidance (the final Code arrives in June 2026, and the official icon will be released then).

When the final Code of Practice publishes in June, compare your program against the final requirements. Update your labeling templates, training materials, and documentation practices to match.

The August 2026 deadline is firm. If you start now, you'll have a working program before the AI Act's transparency obligations take effect. If you wait, you'll be retrofitting compliance onto existing practices. That's harder, slower, and riskier.

You Might Also Like